Search
Search Results (380329 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73398 | 2 Papaki, Wordpress | 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||||
| CVE-2026-73396 | 2026-08-18 | 7.1 High | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73392 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||
| CVE-2026-73382 | 2 Geminilabs, Wordpress | 2 Site Reviews, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | ||||
| CVE-2026-73379 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73377 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73367 | 2 Supsystic, Wordpress | 2 Easy Google Maps, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | ||||
| CVE-2026-73365 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73360 | 2 Premio, Wordpress | 2 Chaty Pro, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | ||||
| CVE-2026-73358 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73352 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | ||||
| CVE-2026-73350 | 2 Psm Plugins, Wordpress | 2 Supportcandy, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | ||||
| CVE-2026-73343 | 2 Aresit, Wordpress | 2 Wp Compress, Wordpress | 2026-08-18 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | ||||
| CVE-2026-73341 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-18 | 9.8 Critical |
| Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | ||||
| CVE-2026-73190 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73187 | 2 Gingerplugins, Wordpress | 2 Sticky Chat Widget, Wordpress | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | ||||
| CVE-2026-72531 | 2026-08-18 | N/A | ||
| Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | ||||
| CVE-2026-71880 | 2026-08-18 | N/A | ||
| Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection | ||||
| CVE-2026-71879 | 2026-08-18 | N/A | ||
| Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | ||||
| CVE-2026-71878 | 2026-08-18 | N/A | ||
| Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass | ||||